Sigma rule conversion #99
-
Hello, I would like to convert the list of sigma rules that I have, to CrowdStrike detection query and Exabeam DL detection query.... is this currently supported? |
Beta Was this translation helpful? Give feedback.
Answered by
thomaspatzke
Jan 26, 2023
Replies: 1 comment 6 replies
-
For CrowdStrike there's a pySigma processing pipeline that converts the field namings, rewrites some values etc. to the CrowdStrike data schema. The Splunk backend then converts into a Splunk query. With Sigma CLI this can be done with:
There's no backend for Exabeam, also not for legacy sigmac. |
Beta Was this translation helpful? Give feedback.
6 replies
Answer selected by
thomaspatzke
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
For CrowdStrike there's a pySigma processing pipeline that converts the field namings, rewrites some values etc. to the CrowdStrike data schema. The Splunk backend then converts into a Splunk query. With Sigma CLI this can be done with:
There's no backend for Exabeam, also not for legacy sigmac.